Skip to main content
Currently onloravaughn.com→ visit Vaughn Cyber Group
Lora Vaughn

// POSTS TAGGED "incident-response"

Incident Response.

All posts tagged incident-response.

← back to all posts

The Slow Call Is Still the Job

Security leadership rewards speed. The calls I am proudest of during an active incident were the ones I forced myself to slow down on. That is a trained discipline, not a personality trait, and most playbooks never write it down.

security-leadershipincident-responsecareerinsights

When Your Vendor Gets Breached, You Find Out Last

A fintech software vendor got hit with ransomware and up to 1.35 million banking customers were exposed. Most of their banks did the questionnaire, got the SOC 2, and still found out months late. The control that matters isn't the one you audited.

community-bankingvendor-riskincident-responseinsights

Your Incident Response Plan Is Modeling the Wrong Threat Actor

LockBit dominated tabletops for years. The ransomware ecosystem has rotated. The groups hitting organizations right now are not the ones your IR team practiced against, and that gap has consequences.

ransomwareincident-responsecommunity-bankingsecurity-leadershipinsights
Featured image for Your Ransomware Negotiator Might Be Playing Both Sides

Your Ransomware Negotiator Might Be Playing Both Sides

The DigitalMint conviction proves your IR vendor pre-vetting is part of your security program, not an afterthought. Here is what to ask before the next incident, not during it.

incident-responsesecurity-operationssecurity-strategyinsights
Featured image for Your Tabletop Exercise Isn't Testing What You Think It Is

Your Tabletop Exercise Isn't Testing What You Think It Is

Most tabletop exercises are scripted theater that confirm what people already believe. Here's what actually breaks during a real incident, and how to design an exercise that finds it before someone else does.

incident-responsetabletop-exercisessecurity-leadershipinsights
Featured image for Why Your Incident Response Plan Will Fail (And What to Build Instead)

Why Your Incident Response Plan Will Fail (And What to Build Instead)

Most IR plans fail not because they're poorly written, but because plans don't survive contact with reality. Here's how to build response capability instead of just documentation.

incident-responsesecurity-operationscrisis-managementtabletop-exercisessecurity-leadershipcisobusiness-continuitysecurity-planninginsights
Featured image for Feats of Endurance and Stupidity: What Running in Circles Teaches Us About Cybersecurity

Feats of Endurance and Stupidity: What Running in Circles Teaches Us About Cybersecurity

What ultramarathon running teaches us about incident response and cybersecurity resilience. Lessons from a CISO on training for chaos, mental endurance, and why preparation beats reaction.

cybersecurityleadershipincident-responseresilience
Featured image for From Jewels to Data: Why We Never Learn

From Jewels to Data: Why We Never Learn

The Louvre got robbed. Companies get breached. Both could've been prevented. Here's why waiting for the 'oh crap' moment is a terrible security strategy.

cybersecurityincident-responsesecurity-strategyrisk-management
Featured image for When Perfect Plans Meet Imperfect Reality

When Perfect Plans Meet Imperfect Reality

Sometimes the consequences of IR plan failure aren't just about downtime or data. Sometimes they're about life and death.

incident-responsecybersecurityhealthcaresecurity-leadershipinsights
Featured image for The Question That Made Everyone in the Room Go Silent

The Question That Made Everyone in the Room Go Silent

I asked one simple question about incident response plans. The silence that followed told me everything I needed to know.

incident-responsecybersecuritysecurity-leadership